Description
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
gracepure (VulDB User)
References
vuldb.com/vuln/367536 (VDB-367536 | itsourcecode Content Management System save_comment.php sql injection)
vuldb.com/vuln/367536/cti (VDB-367536 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10256 (CVE-2026-10256 | CVE Analysis and Report)
vuldb.com/submit/824155 (Submit #824155 | itsourcecode Content Management System V1.0 SQL Injection)
github.com/wsjjllk/cve/issues/1
itsourcecode.com/